Jim Manico -- The Extremely Unabridged History of SQLi and XSS episode artwork

EPISODE · Dec 3, 2018 · 30 MIN

Jim Manico -- The Extremely Unabridged History of SQLi and XSS

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why are SQL injection and cross-site scripting still with us after years of knowing how to prevent them? Jim Manico joins Chris for an informal journey through the history of both vulnerability classes and the defenses that changed application development. They discuss parameterized database APIs, output encoding, sanitization, framework defaults, and the long life of legacy software. The conversation then turns toward the future: what security libraries and language-specific analysis can do, where commercial testing tools fit, and who has an incentive to invest in stronger platforms. Jim’s recollections and predictions make this an opinionated archive conversation about progress and persistence, with a central challenge for developers and security teams: make protection a normal part of building software.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Jim Manico:→ Jim Manico on LinkedInMentioned in this episode:→ DOMPurify→ OWASP ESAPI→ Go html/template→ Brakeman→ OWASP Top 10Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The history of SQL injection and XSS with Jim Manico01:33 How application security has changed05:06 Parameterized queries and early defenses07:20 Why injection remains on the Top 1009:22 Could SQL injection disappear?10:39 Tracing the history of cross-site scripting17:21 Carrying secure defaults into new frameworks19:34 Legacy applications and long software lifespans20:47 The role of defensive technology23:13 What happens to the security tool market?24:52 Why language-specific analysis matters26:26 Who pays for more secure platforms?

Episode metadata supplied by the publisher feed · Published Dec 3, 2018

Embed this episode

Why are SQL injection and cross-site scripting still with us after years of knowing how to prevent them? Jim Manico joins Chris for an informal journey through the history of both vulnerability classes and the defenses that changed application development. They discuss parameterized database APIs, output encoding, sanitization, framework defaults, and the long life of legacy software. The conversation then turns toward the future: what security libraries and language-specific analysis can do,...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Jim Manico -- The Extremely Unabridged History of SQLi and XSS

0:00 30:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 30 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on December 3, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!